CAPTAIN Protocol Adapter for Tactical Network Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current In-Line Network Encryptor (INE) devices impair the operation of networking protocols and network optimization techniques, particularly in tactical networks with dynamically varying link characteristics and asymmetric links, and preclude operations like multicast and disruption tolerant networking, while also rendering cybersecurity less effective due to limitations in deep packet inspection.

Innovation Solution

The Crypto-Partitioning Aware Protocol adapter for Tactical Networks (CAPTAIN) intercepts data packets, identifies unencrypted fields, and populates them with messages that can be read by other protocol adapters, enabling the implementation of performance-enhancing proxy functions across INEs, such as HAIPE devices, to facilitate unimpeded protocol operations and security protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data packets are encrypted by INE devices to protect sensitive content in untrusted networks, then security against eavesdropping is improved, but protocol operation and network optimization techniques are impaired

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the data packet into different parts: encrypted payload content and unencrypted pass-through fields. This segmentation allows the encrypted portion to provide security while the unencrypted portion enables protocol operations and network optimization techniques to function across the INE device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces protocol adapters as intermediary devices that populate pass-through fields with appropriate information before encryption and interpret these fields after decryption. These adapters enable protocol operations to work across the encrypted link without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep packet inspection is blocked by encryption to maintain security, then security is improved, but cybersecurity effectiveness is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidcybersecurity effectiveness
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the packet into encrypted content and unencrypted pass-through fields, allowing security mechanisms to inspect the unencrypted fields for threats while the encrypted content remains protected. This enables cybersecurity effectiveness without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Protocol adapters act as intermediaries that populate pass-through fields with information that can be inspected by security systems. This allows deep packet inspection to function on the unencrypted fields while the main content remains encrypted and secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all data fields are encrypted to ensure security, then security is improved, but network optimization and protocol functions cannot operate

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork optimization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the data packet into encrypted and unencrypted segments, with pass-through fields remaining unencrypted to enable network optimization functions while the main content stays encrypted for security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption qualities to different parts of the packet: full encryption for sensitive content and no encryption for pass-through fields that need to be processed by network optimization functions and protocol adapters.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9887974B2Method for network communication past encryption devices
Publication Date: 2018.02.06 ARCHITECTURE TECH CORP
  • US9887974B2 patent drawing
  • US9887974B2 patent drawing
  • US9887974B2 patent drawing

AI summary

This disclosure is directed to techniques for providing communication between devices in different networks wherein the communication must first pass through an encryption mechanism and the devices do not have the stand-alone capability to encrypt or decrypt the communication. According to these techniques, an adapter may determine certain fields in a data packet that remain unencrypted when the data packet passes through the encryption mechanism. The adapter may then process those fields in such a way that, when the data packets are received by a second adapter, the second adapter may read those fields and obtain information.